| CR-01 |
critical |
fixed |
Fixed in be4a923 (tests a13a121), quick 260927-q23. Admin refresh now applies the backend guard's subject checks (activated, not deleted, iat not before tokens_valid_after) via bouncer.RefreshAudienceFor before minting, and a refused cookie refresh expires summer_admin. |
| WR-01 |
warning |
open |
Logout does not expire the cookie when the token is rejected |
| WR-02 |
warning |
open |
A belongsTo foreign key exposed as a scalar field skips the relation scope check |
| WR-03 |
warning |
open |
Model rules run before relation values are assigned |
| WR-04 |
warning |
open |
Scope filter choices cannot be scoped to the signed-in admin |
| WR-05 |
warning |
open |
SPA loaders have no error handling, so network failures leave views stuck loading |
| WR-06 |
warning |
open |
After a delete or unlink, the list can stay on a page past the last page |
| WR-07 |
warning |
open |
Refresh re-mints iat, so the refresh window slides with no upper bound |
| IN-01 |
info |
open |
A large access TTL makes the proactive refresh fire in a loop |
| IN-02 |
info |
open |
Nothing enforces the CSRF design's "no preflight on the admin API" assumption |
| IN-03 |
info |
open |
Choosing the transport by X-Requested-With is fragile for Bearer clients |
| IN-04 |
info |
open |
Dead genre and style cases in the albums DropdownOptions |
| IN-05 |
info |
open |
Relation id lists have no size cap |
| IN-06 |
info |
open |
The gate's required-test check ignores the package |
| IN-07 |
info |
open |
Logging out from a dirty form can leave the user on the form without a session |
| WR-08 |
warning |
open |
The frontend user refresh still ignores tokens_valid_after, so the CR-01 gap remains for site users (added by re-review 2026-09-27) |
| IN-08 |
info |
open |
bouncer.Middleware still inlines the subject lookup that subjectPrincipal now owns (added by re-review 2026-09-27) |
| IN-09 |
info |
open |
RefreshAudienceFor takes a request context but the blacklist calls ignore it (added by re-review 2026-09-27) |
| IN-10 |
info |
open |
service.users is documented as the backend guard's provider, which is not guaranteed (added by re-review 2026-09-27) |